Various laws, including the EU's GDPR 2016/679 and the CCPA impose obligations restricting the collection, use and transfer of personal data. The U.S. Federal Trade Commission and various states enforce consumer protection laws to impose obligations on the collection and use of consumer data and on security measures for protecting that data. Similarly, any country that we may enter into for business may have related or more stringent personal data, consumer protection and cybersecurity requirements.
The obligations that these laws and regulations impose can be extensive, including, but not limited to, restrictions on when data can be collected from a person, requirements to obtain consent to collect data from a person, requirements to disclose how data is collected, used and stored, requirements for extensive record keeping on systems processing personal data, geographic limitations on where the data can be stored and processed, contractual obligations that must be maintained with data providers and data recipients, standard contract clauses approved by the EU when transferring data outside of the European Economic Area, responding to consumer inquiries, notifying regulatory authorities about data breaches, and designating data protection officers. We have incorporated into our platform and our operations features and processes that we believe allow us to comply with these types of laws and regulations in the locations where we currently collect data. Before we begin services into a new country, we review applicable laws and regulations and create a plan to update our systems and operating procedures, if necessary, to comply with all local data and related consumer protection requirements.
In addition, we maintain operations in the UK, which has left the EU. The EU Commission has released a draft decision declaring UK data protection obligations adequate, which, if ratified, would allow flow of data between from the EU to the UK with the same benefits as when the UK was part of the EU. If the decision is not ratified, we will be required to follow additional procedures, including implementing standard contract clauses approved by the EU to transfer data adequacy for processing or storage in the UK.
Failure to comply with any of the laws and regulations discussed in this section can result in fines and penalties. For example, failing to comply with the GDPR can trigger fines equal to or greater of €20 million or 4% of global annual revenues. If at any time our platform or operations are found noncompliant with these requirements, our business, results of operations, and financial condition may be materially and adversely impacted.
Meeting the obligations imposed by any of the above laws and regulations or any similar laws and regulations that may apply to our current and future business will impact our business. We will incur expenses investing in technology and procedures that allow our operations to comply with the applicable laws and regulations. We may be forced to store and process data in certain regions or countries. While we have taken this into account with our current plans, it is possible that complying with these requirements will require the business to spend additional expenses on operations, storage, and/or processing to meet our obligations.
Restrictions on the collection, use, sharing or disclosure of personal data or additional requirements and liability for security and data integrity may require us to modify our business practices, limit our ability to develop new products and features and subject us to increased compliance obligations and regulatory scrutiny. In addition, many consumer advocates, privacy advocates, and government regulators believe that existing laws and regulations do not adequately protect privacy or ensure the accuracy of personal data. As a result, such advocates and regulators are seeking further restrictions on the dissemination or commercial use of personal information to the public and private sectors, as well as contemplating requirements relative to data accuracy and the ability of consumers to opt to have their personal data removed from databases such as ours. If there are new data limitations in any jurisdiction in which we currently do business in or plan to enter to do business, our ability to offer our products and services may be materially impacted. For example, new restrictions may require additional investment in our technology, may limit the availability of data that we obtain, or may impose new requirements on how data is collected. These restrictions may be unique to certain countries or regions and could be inconsistent with requirements in other countries or regions. Any of these factors has the potential to reduce the profitability of our products and services, or to reduce our ability to offer our products and services, and our business, results of operations, and financial condition may be materially and adversely impacted.
In addition, additional jurisdictions may impose data localization laws, which require personal information, or certain subcategories of personal information to be stored in the jurisdiction of origin. These regulations may inhibit our ability to expand into those markets or prohibit us from continuing to offer our marketplace in those markets without significant additional costs.
Typically, our obligations to comply with the regulations and laws discussed in this section are reflected in our contracts with our data providers. If we or our customers fail to comply with the laws and regulations discussed in this section, our OEM data providers may decide to reduce or terminate availability of their connected vehicle data, impose further limitations upon us that impact our ability to provide data to our customers, or terminate their contracts with us.
OEMs that provide us data are typically bound by the same or similar regulatory requirements that we face. If our OEM data providers fail to comply with the laws and regulations discussed in this section, they could be subject to fines and new requirements on their systems and their ability to provide us connected vehicle data may be reduced or interrupted entirely. They may also face pressure from consumer advocates, privacy advocates, and government regulators who believe that existing practices, laws and regulations do not adequately protect privacy or ensure the accuracy of personal data. One consequence of this is that they may decide to comply with the laws and regulations or respond to pressure from various consumer and privacy advocates in a manner that may adversely impact our ability to deliver our products and services, either by increasing costs or by deciding not to make connected vehicle data available.
If we fail to comply with any of these laws or regulations or any of our data providers or customers fail to comply with these laws or regulations, the result could include fines and penalties, harm to reputation, and negative impact on the results of our operations and financial condition.